Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F05111397040753F0A8372E1B76273ABB3E19542DA17171151F587AC0FDEE8BCE2654A |
|
CONTENT
ssdeep
|
48:TmjdeON3MsQlILb+kwsvSUMc62o44/4Oj2o8HdHtw9X3Gg:TmjBN8s3jHlCH1v890Wg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3671ccc4c363167 |
|
VISUAL
aHash
|
00e7c7e7e7ffffff |
|
VISUAL
dHash
|
aa4d4d4d4ca8b1b1 |
|
VISUAL
wHash
|
00030303c3cfdfdf |
|
VISUAL
colorHash
|
06000000007 |
|
VISUAL
cropResistant
|
284d4d4d4cb8b1b9,0000081010100800,bf9ffef8f8f0e646 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.